PT-2020-13439 · Gitlab · Gitlab

Published

2020-09-14

·

Updated

2024-03-06

·

CVE-2020-13298

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 13.1.10 GitLab versions prior to 13.2.8 GitLab versions prior to 13.3.4
Description A vulnerability was discovered in GitLab where the Conan package upload functionality did not properly validate the supplied parameters. This resulted in limited files disclosure.
Recommendations For versions prior to 13.1.10, update to version 13.1.10 or later. For versions prior to 13.2.8, update to version 13.2.8 or later. For versions prior to 13.3.4, update to version 13.3.4 or later.

Fix

Related Identifiers

BIT-GITLAB-2020-13298
CVE-2020-13298

Affected Products

Gitlab